PT-2010-1174 · Microsoft · Office Powerpoint
Alin Rad Pop
·
Publicado
2010-11-09
·
Atualizado
2025-03-26
·
CVE-2010-2572
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft PowerPoint versions 2002 SP3 through 2003 SP3
Description
The issue is a buffer overflow in Microsoft PowerPoint, allowing remote attackers to execute arbitrary code via a crafted PowerPoint 95 document. This can give an attacker full control over the system, enabling them to install programs, view, modify, and delete data, as well as create new accounts with full user rights.
Recommendations
For Microsoft PowerPoint versions 2002 SP3 and 2003 SP3, consider disabling the handling of PowerPoint 95 documents until a patch is available.
As a temporary workaround, restrict access to the vulnerable component that handles PowerPoint 95 files to minimize the risk of exploitation.
Avoid using the vulnerable version of Microsoft PowerPoint to open specially crafted PowerPoint 95 documents until the issue is resolved.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Office Powerpoint